PT-2024-6857 · Linux+1 · Linux Kernel+1

Published

2024-07-20

·

Updated

2024-09-06

·

CVE-2024-42254

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to inconsistent error handling in the io alloc pbuf ring() function within the io uring subsystem of the Linux kernel, which can lead to a null pointer dereference. This could potentially allow an attacker to cause a denial of service. The problem is identified by Syz and is associated with a null pointer dereference in the range [0x0000000000000000-0x0000000000000007]. The call trace includes functions such as io remove buffers(), io put bl(), io destroy buffers(), and io ring ctx free(). There is no information provided about the estimated number of potentially affected devices or real-world incidents where this issue was exploited.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-08079
CVE-2024-42254

Affected Products

Astra Linux
Linux Kernel